← Back

Claws Mail

claws-mail

Vendor: Claws Mail • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Claws Mail
FedoraprojectSylpheed Project
3Claws Mail
FedoraSylpheed
Nov 21, 2024
Jul 30, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
2Claws Mail
Fedoraproject
2Claws Mail
Fedora
Nov 21, 2024
Jul 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
3Claws Mail
FedoraprojectOpensuse
4Backports Sle
Claws MailFedora+1 more
Nov 21, 2024
Jul 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
1Claws Mail
1Claws Mail
May 6, 2026
Apr 11, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: thi...Show more
Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8614.Show less
2Claws Mail
Opensuse
3Claws Mail
LeapOpensuse
May 6, 2026
Apr 11, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafte...Show more
Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.Show less
2Claws Mail
Opensuse
2Claws Mail
Opensuse
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM)...Show more
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.Show less
1Claws Mail
1Claws Mail
Apr 29, 2026
Oct 22, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The strchr function in procmime.c in Claws Mail (aka claws-mail) 3.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted email.